CVE-2024-4877Privilege Chaining in Openvpn

CWE-268Privilege Chaining6 documents6 sources
Severity
8.8HIGHNVD
EPSS
0.2%
top 53.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3

Description

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages4 packages

NVDopenvpn/openvpn2.4.02.6.11
Alpineopenvpn/openvpn< 0+5
CVEListV5openvpn/openvpn2.4.02.6.11

🔴Vulnerability Details

3
GHSA
GHSA-c26r-vw7p-2m7h: OpenVPN version 22025-04-03
CVEList
CVE-2024-4877: OpenVPN version 22025-04-03
OSV
CVE-2024-4877: OpenVPN version 22025-04-03

📋Vendor Advisories

2
CISA ICS
Siemens SINEMA Remote Connect Client2025-03-13
Debian
CVE-2024-4877: openvpn - OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privi...2024